<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD VPN Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122874#M1113241</link>
    <description>&lt;P&gt;&lt;BR /&gt;&amp;gt; packet-tracer input INSIDE tcp 10.90.90.45 34654 172.16.105.137 3389&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: UN-NAT&lt;/P&gt;&lt;P&gt;Subtype: static&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (INTERNET,INSIDE) source static Cloud-External-PRI Cloud-External-PRI destination static Cloud-Group Cloud-Group&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;NAT divert to egress interface INTERNET(vrfid:0)&lt;/P&gt;&lt;P&gt;Untranslate 172.16.105.137/3389 to 172.16.105.137/3389&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group CSM_FW_ACL_ global&lt;/P&gt;&lt;P&gt;access-list CSM_FW_ACL_ advanced permit ip any ifc INTERNET any rule-id 268446727&lt;/P&gt;&lt;P&gt;access-list CSM_FW_ACL_ remark rule-id 268446727: ACCESS POLICY: ACCESS_CONTROL_POLICY - Mandatory&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;This packet will be sent to snort for additional processing where a verdict will be reached&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: CONN-SETTINGS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;class-map class-default&lt;/P&gt;&lt;P&gt;match any&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class class-default&lt;/P&gt;&lt;P&gt;set connection advanced-options UM_STATIC_TCP_MAP&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (INTERNET,INSIDE) source static Cloud-External-PRI Cloud-External-PRI destination static Cloud-Group Cloud-Group&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Static translate 10.90.90.45/34654 to 10.90.90.45/34654&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: per-session&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;/P&gt;&lt;P&gt;Type: FLOW-EXPORT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 8&lt;/P&gt;&lt;P&gt;Type: VPN&lt;/P&gt;&lt;P&gt;Subtype: encrypt&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: INSIDE(vrfid:0)&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: INTERNET(vrfid:0)&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule, Drop-location: frame 0x000000aaada3b8e8 flow (NA)/NA&lt;/P&gt;</description>
    <pubDate>Sun, 02 Jun 2024 08:27:55 GMT</pubDate>
    <dc:creator>N3om</dc:creator>
    <dc:date>2024-06-02T08:27:55Z</dc:date>
    <item>
      <title>FTD VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122272#M1113208</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;So we have an already working&amp;nbsp; Site to Site VPN on our FTD,&amp;nbsp; I have ran into an issue with the FTD I have added a couple of IP Addresses in the config and added an ACL allowing RDP and also used the same NAT rule as the working IPs, when I run packet tracer its says VPN Block but when I look at the connections when running packet tracer it show the traffic blocked, any idea why the ACL in the packetracer is Allow but in connection logs its blocking and VPN says Block in packe tracer.??&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2024 22:19:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122272#M1113208</guid>
      <dc:creator>N3om</dc:creator>
      <dc:date>2024-05-31T22:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122321#M1113211</link>
      <description>&lt;P&gt;You need show us some screenshot to understand - other than new added ACL and NAT, before you have anything working ?&lt;/P&gt;
&lt;P&gt;if this is S2S VPN do you have other side also should have same kind of rule to get the traffic in.&lt;/P&gt;
&lt;P&gt;Packet tracer is just to see the flows , have you tried real time try to access RDP from or to clients ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2024 06:17:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122321#M1113211</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-06-01T06:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122459#M1113230</link>
      <description>&lt;P&gt;can I see the packet-tracer you use and it result ?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2024 10:11:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122459#M1113230</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-01T10:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122874#M1113241</link>
      <description>&lt;P&gt;&lt;BR /&gt;&amp;gt; packet-tracer input INSIDE tcp 10.90.90.45 34654 172.16.105.137 3389&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: UN-NAT&lt;/P&gt;&lt;P&gt;Subtype: static&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (INTERNET,INSIDE) source static Cloud-External-PRI Cloud-External-PRI destination static Cloud-Group Cloud-Group&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;NAT divert to egress interface INTERNET(vrfid:0)&lt;/P&gt;&lt;P&gt;Untranslate 172.16.105.137/3389 to 172.16.105.137/3389&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group CSM_FW_ACL_ global&lt;/P&gt;&lt;P&gt;access-list CSM_FW_ACL_ advanced permit ip any ifc INTERNET any rule-id 268446727&lt;/P&gt;&lt;P&gt;access-list CSM_FW_ACL_ remark rule-id 268446727: ACCESS POLICY: ACCESS_CONTROL_POLICY - Mandatory&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;This packet will be sent to snort for additional processing where a verdict will be reached&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: CONN-SETTINGS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;class-map class-default&lt;/P&gt;&lt;P&gt;match any&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class class-default&lt;/P&gt;&lt;P&gt;set connection advanced-options UM_STATIC_TCP_MAP&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (INTERNET,INSIDE) source static Cloud-External-PRI Cloud-External-PRI destination static Cloud-Group Cloud-Group&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Static translate 10.90.90.45/34654 to 10.90.90.45/34654&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: per-session&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;/P&gt;&lt;P&gt;Type: FLOW-EXPORT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 8&lt;/P&gt;&lt;P&gt;Type: VPN&lt;/P&gt;&lt;P&gt;Subtype: encrypt&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: INSIDE(vrfid:0)&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: INTERNET(vrfid:0)&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule, Drop-location: frame 0x000000aaada3b8e8 flow (NA)/NA&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 08:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122874#M1113241</guid>
      <dc:creator>N3om</dc:creator>
      <dc:date>2024-06-02T08:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122876#M1113243</link>
      <description>&lt;P&gt;Do the packet tracer again share result&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also can I see the NAT you use? Why you not use inside as sourcr interface?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 08:37:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122876#M1113243</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-02T08:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122880#M1113244</link>
      <description>&lt;P&gt;The nat is bidirectional the rule states INTERNET- INSIDE&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 08:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122880#M1113244</guid>
      <dc:creator>N3om</dc:creator>
      <dc:date>2024-06-02T08:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122903#M1113249</link>
      <description>&lt;P&gt;Yes i know that' how yoh config it&lt;/P&gt;
&lt;P&gt;Is it auto or manaul NAT?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 10:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122903#M1113249</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-02T10:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122905#M1113250</link>
      <description>&lt;P&gt;Manual NAT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 10:40:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122905#M1113250</guid>
      <dc:creator>N3om</dc:creator>
      <dc:date>2024-06-02T10:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122907#M1113251</link>
      <description>&lt;P&gt;Do packet tracer again and share result.&lt;/P&gt;
&lt;P&gt;With&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Debug crypto isakmp 127&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you run IKEv1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 10:52:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122907#M1113251</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-02T10:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122909#M1113252</link>
      <description>&lt;P&gt;Its IKEv2&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 10:57:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122909#M1113252</guid>
      <dc:creator>N3om</dc:creator>
      <dc:date>2024-06-02T10:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: FTD VPN Issue</title>
      <link>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122914#M1113254</link>
      <description>&lt;P&gt;Debug crypto ikev2 protocol 9&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 02 Jun 2024 11:04:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-vpn-issue/m-p/5122914#M1113254</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-06-02T11:04:06Z</dc:date>
    </item>
  </channel>
</rss>

